A Blockchain based ReDoS Cyber Threat Intelligence Sharing System for Privacy-preserving and Incentive Comparability
As cybersecurity challenges become increasingly severe and many new attacks emerge, Regular Expression Denial of Service (ReDoS) attack is one of most practical threats, which has not garnered widespread attentions yet in the industries. This attack exploits potential design flaws of regular expressions in web services, significantly degrading the performance of target systems and posing serious threats to service availability. Current detection methods typically require numerous known ReDoS vulnerability patterns which are generated by ever attacked service servers. Therefore, a platform for sharing ReDoS cyber threat intelligence (CTI) is crucial, however, the traditional CTI sharing platforms bear the issues of data privacy leakage and lack of sufficient incentives for sharing their CTI. In this paper, we propose a blockchain based ReDoS CTI sharing mechanism to preserve CTI privacy and provide evolutionary game theory compatible incentives for CTI contributors. In our design, considering he distributed nature of ReDoS CTI contributors, we construct a ReDoS CTI sharing platform based on the consortium blockchain infrastructure, where all the CTI sharing related records are stored in a secure and immutable manner. To prevent potential CTI privacy leakage risks due to the transparency property of block data, we design an attribute-based encryption based CTI access control protocol, enabling ciphertext search functionality while preserving CTI data privacy. We further design an incentive mechanism based on evolutionary game theory to encourage stakeholders to actively share high-quality ReDoS CTI, where the value of ReDoS CTI is determined by the effectiveness in successfully defense against ReDos attacks. Simulation and real data based experimental results demonstrate the efficiency of our proposed system. Our study provides a blockchain based CTI sharing solution to encourage valuable ReDoS CTI shared effectively and efficiently in a privacy preserved way.
Fri 26 JulDisplayed time zone: Beijing, Chongqing, Hong Kong, Urumqi change
13:30 - 15:15 | Session 2 - Blockchain-based ApplicationResearch Track at The ballroom B Chair(s): Jiachi Chen Sun Yat-sen University | ||
13:30 15mPaper | A Blockchain based ReDoS Cyber Threat Intelligence Sharing System for Privacy-preserving and Incentive Comparability Research Track Yanran Tang Guangzhou University, Mengqing Cheng Guangzhou University, Mengyu Wang Guangzhou University, Yuan Zhou , Yuan Liu Guangzhou University, Chunming Rong University of Stavanger, Norway, Zhihong Tian Guangzhou university | ||
13:45 15mPaper | Empowering Autonomous IoT Devices in Blockchain through Gasless Transactions Research Track Yash Madhwal Skolkovo Institute of Science and Technology, Yury Yanovich Skolkovo Institute of Science and Technology; Faculty of Computer Science, HSE University, Aleksandra Korotkevich HSE University, Daria Parshina HSE University, Nshteh Seropian HSE University, Stepan Gavrilov ITMO University, Alex Nikolaev Moscow Institute of Physics and Technology, S. Balachander SRM Institute of Science and Technology, A. Murugan SRM Institute of Science and Technology | ||
14:00 15mPaper | A Blockchain based Efficient Incentive Mechanism in Tripartite Cyber Threat Intelligence Service Marketplace Research Track Yuan Zhou , Yuan Liu Guangzhou University, YaoYao Zhang Guangzhou university, Yang Qinglin Guangzhou University, Chunming Rong University of Stavanger, Norway, Zhihong Tian Guangzhou university | ||
14:15 15mPaper | Blockchain-Driven Innovation in Fashion Supply Chain Contractual Party Evaluations as an Emerging Collaboration Model Research Track Minhao Qiao The Hong Kong Polytechnic University, Xuanchang Chen The Hong Kong Polytechnic University, Yangping Zhou The Hong Kong Polytechnic University, P. Y. Mok The Hong Kong Polytechnic University | ||
14:30 15mPaper | The Implementation of Open Banking Under the Sovereign Blockchain Theory Research Track Mi Wang Liaoning University | ||
14:45 15mPaper | A Blockchain-based Trusted Sharing Method for Railway Transportation BIM Data Research Track Chenhao Wang Zhejiang University, Xiaogang Wang China Railway Engineering Design & Consulting Group Co. | ||
15:00 15mPaper | Security-aware Transactive Energy System with Virtual Power Plants Through Blockchain and Multi-Signature Research Track Peng Zhang Shenzhen University, Junpeng Peng Shenzhen University, Yuhong Liu Santa Clara University, Zujie Tang Shenzhen University |